Hacker News new | ask | show | jobs
by bsaul 1161 days ago
In the scenario you're describing, what would let whatsapp know it actually shouldn't register that new device in the public key repository ?

Either whatsapp knows the phone is hacking the account to a new number / device, in which case it should simply disable it, or it doesn't and then it will treat it exactly like a normal one.

1 comments

Well the pubic key would refresh and the other side could see that. I think whatsapp already sends public key refreshes anyway.